Taehee Yoo
71a8508402
net: bpfilter: disallow to remove bpfilter module while being used
The bpfilter.ko module can be removed while functions of the bpfilter.ko
are executing. so panic can occurred. in order to protect that, locks can
be used. a bpfilter_lock protects routines in the
__bpfilter_process_sockopt() but it's not enough because __exit routine
can be executed concurrently.
Now, the bpfilter_umh can not run in parallel.
So, the module do not removed while it's being used and it do not
double-create UMH process.
The members of the umh_info and the bpfilter_umh_ops are protected by
the bpfilter_umh_ops.lock.
test commands:
while :
do
iptables -I FORWARD -m string --string ap --algo kmp &
modprobe -rv bpfilter &
done
splat looks like:
[ 298.623435] BUG: unable to handle kernel paging request at fffffbfff807440b
[ 298.628512] #PF error: [normal kernel read fault]
[ 298.633018] PGD 124327067 P4D 124327067 PUD 11c1a3067 PMD 119eb2067 PTE 0
[ 298.638859] Oops: 0000 [#1] SMP DEBUG_PAGEALLOC KASAN PTI
[ 298.638859] CPU: 0 PID: 2997 Comm: iptables Not tainted 4.20.0+ #154
[ 298.638859] RIP: 0010:__mutex_lock+0x6b9/0x16a0
[ 298.638859] Code: c0 00 00 e8 89 82 ff ff 80 bd 8f fc ff ff 00 0f 85 d9 05 00 00 48 8b 85 80 fc ff ff 48 bf 00 00 00 00 00 fc ff df 48 c1 e8 03 <80> 3c 38 00 0f 85 1d 0e 00 00 48 8b 85 c8 fc ff ff 49 39 47 58 c6
[ 298.638859] RSP: 0018:ffff88810e7777a0 EFLAGS: 00010202
[ 298.638859] RAX: 1ffffffff807440b RBX: ffff888111bd4d80 RCX: 0000000000000000
[ 298.638859] RDX: 1ffff110235ff806 RSI: ffff888111bd5538 RDI: dffffc0000000000
[ 298.638859] RBP: ffff88810e777b30 R08: 0000000080000002 R09: 0000000000000000
[ 298.638859] R10: 0000000000000000 R11: 0000000000000000 R12: fffffbfff168a42c
[ 298.638859] R13: ffff888111bd4d80 R14: ffff8881040e9a05 R15: ffffffffc03a2000
[ 298.638859] FS: 00007f39e3758700(0000) GS:ffff88811ae00000(0000) knlGS:0000000000000000
[ 298.638859] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 298.638859] CR2: fffffbfff807440b CR3: 000000011243e000 CR4: 00000000001006f0
[ 298.638859] Call Trace:
[ 298.638859] ? mutex_lock_io_nested+0x1560/0x1560
[ 298.638859] ? kasan_kmalloc+0xa0/0xd0
[ 298.638859] ? kmem_cache_alloc+0x1c2/0x260
[ 298.638859] ? __alloc_file+0x92/0x3c0
[ 298.638859] ? alloc_empty_file+0x43/0x120
[ 298.638859] ? alloc_file_pseudo+0x220/0x330
[ 298.638859] ? sock_alloc_file+0x39/0x160
[ 298.638859] ? __sys_socket+0x113/0x1d0
[ 298.638859] ? __x64_sys_socket+0x6f/0xb0
[ 298.638859] ? do_syscall_64+0x138/0x560
[ 298.638859] ? entry_SYSCALL_64_after_hwframe+0x49/0xbe
[ 298.638859] ? __alloc_file+0x92/0x3c0
[ 298.638859] ? init_object+0x6b/0x80
[ 298.638859] ? cyc2ns_read_end+0x10/0x10
[ 298.638859] ? cyc2ns_read_end+0x10/0x10
[ 298.638859] ? hlock_class+0x140/0x140
[ 298.638859] ? sched_clock_local+0xd4/0x140
[ 298.638859] ? sched_clock_local+0xd4/0x140
[ 298.638859] ? check_flags.part.37+0x440/0x440
[ 298.638859] ? __lock_acquire+0x4f90/0x4f90
[ 298.638859] ? set_rq_offline.part.89+0x140/0x140
[ ... ]
Fixes: d2ba09c17a ("net: add skeleton of bpfilter kernel module")
Signed-off-by: Taehee Yoo <ap420073@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
|
2019-01-11 18:05:41 -08:00 |
| .. |
|
bpfilter
|
net: bpfilter: disallow to remove bpfilter module while being used
|
2019-01-11 18:05:41 -08:00 |
|
netfilter
|
Merge git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf-next
|
2018-12-20 18:20:26 -08:00 |
|
af_inet.c
|
net: use indirect call wrappers at GRO transport layer
|
2018-12-15 13:23:02 -08:00 |
|
ah4.c
|
net-ipv4: remove 2 always zero parameters from ipv4_redirect()
|
2018-09-26 20:30:55 -07:00 |
|
arp.c
|
net: Evict neighbor entries on carrier down
|
2018-10-12 09:47:39 -07:00 |
|
cipso_ipv4.c
|
|
|
|
datagram.c
|
ipv4: Allow sending multicast packets on specific i/f using VRF socket
|
2018-10-02 22:28:17 -07:00 |
|
devinet.c
|
netlink: fixup regression in RTM_GETADDR
|
2019-01-04 12:47:06 -08:00 |
|
esp4.c
|
net: use skb_sec_path helper in more places
|
2018-12-19 11:21:37 -08:00 |
|
esp4_offload.c
|
net: use skb_sec_path helper in more places
|
2018-12-19 11:21:37 -08:00 |
|
fib_frontend.c
|
net: Don't return invalid table id error when dumping all families
|
2018-10-24 14:06:25 -07:00 |
|
fib_lookup.h
|
|
|
|
fib_notifier.c
|
|
|
|
fib_rules.c
|
ipv4: fib_rules: Fix possible infinite loop in fib_empty_table
|
2018-12-30 12:57:04 -08:00 |
|
fib_semantics.c
|
net: Add extack argument to ip_fib_metrics_init
|
2018-11-06 15:00:45 -08:00 |
|
fib_trie.c
|
net/ipv4: Plumb support for filtering route dumps
|
2018-10-16 00:13:12 -07:00 |
|
fou.c
|
fou: Prevent unbounded recursion in GUE error handler also with UDP-Lite
|
2019-01-04 13:06:07 -08:00 |
|
gre_demux.c
|
net: Convert protocol error handlers from void to int
|
2018-11-08 17:13:08 -08:00 |
|
gre_offload.c
|
|
|
|
icmp.c
|
net: Convert protocol error handlers from void to int
|
2018-11-08 17:13:08 -08:00 |
|
igmp.c
|
ipv4/igmp: fix v1/v2 switchback timeout based on rfc3376, 8.12
|
2018-10-29 20:26:06 -07:00 |
|
inet_connection_sock.c
|
inet: minor optimization for backlog setting in listen(2)
|
2018-11-07 22:31:07 -08:00 |
|
inet_diag.c
|
tcp: fix a race in inet_diag_dump_icsk()
|
2018-12-20 19:23:22 -08:00 |
|
inet_fragment.c
|
inet: frags: better deal with smp races
|
2018-11-08 18:40:30 -08:00 |
|
inet_hashtables.c
|
net: dccp: fix kernel crash on module load
|
2018-12-24 15:27:56 -08:00 |
|
inet_timewait_sock.c
|
|
|
|
inetpeer.c
|
|
|
|
ip_forward.c
|
Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net
|
2018-12-20 11:53:36 -08:00 |
|
ip_fragment.c
|
net: ipv4: do not handle duplicate fragments as overlapping
|
2018-12-15 11:50:40 -08:00 |
|
ip_gre.c
|
ip: validate header length on virtual device xmit
|
2019-01-01 12:05:02 -08:00 |
|
ip_input.c
|
Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net
|
2018-12-09 21:43:31 -08:00 |
|
ip_options.c
|
|
|
|
ip_output.c
|
sk_buff: add skb extension infrastructure
|
2018-12-19 11:21:37 -08:00 |
|
ip_sockglue.c
|
ip: on queued skb use skb_header_pointer instead of pskb_may_pull
|
2019-01-10 09:27:20 -05:00 |
|
ip_tunnel.c
|
ip: validate header length on virtual device xmit
|
2019-01-01 12:05:02 -08:00 |
|
ip_tunnel_core.c
|
Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net
|
2018-12-24 16:19:56 -08:00 |
|
ip_vti.c
|
ip: validate header length on virtual device xmit
|
2019-01-01 12:05:02 -08:00 |
|
ipcomp.c
|
net-ipv4: remove 2 always zero parameters from ipv4_redirect()
|
2018-09-26 20:30:55 -07:00 |
|
ipconfig.c
|
Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net
|
2018-12-20 11:53:36 -08:00 |
|
ipip.c
|
net: Convert protocol error handlers from void to int
|
2018-11-08 17:13:08 -08:00 |
|
ipmr.c
|
Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net
|
2018-12-20 11:53:36 -08:00 |
|
ipmr_base.c
|
Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net
|
2018-10-19 11:03:06 -07:00 |
|
Kconfig
|
|
|
|
Makefile
|
bpf, sockmap: convert to generic sk_msg interface
|
2018-10-15 12:23:19 -07:00 |
|
metrics.c
|
net: Add extack argument to ip_fib_metrics_init
|
2018-11-06 15:00:45 -08:00 |
|
netfilter.c
|
|
|
|
netlink.c
|
|
|
|
ping.c
|
ipv4: Allow sending multicast packets on specific i/f using VRF socket
|
2018-10-02 22:28:17 -07:00 |
|
proc.c
|
tcp: implement coalescing on backlog queue
|
2018-11-30 13:26:54 -08:00 |
|
protocol.c
|
fou, fou6: ICMP error handlers for FoU and GUE
|
2018-11-08 17:13:08 -08:00 |
|
raw.c
|
Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net
|
2018-12-20 11:53:36 -08:00 |
|
raw_diag.c
|
|
|
|
route.c
|
net: ipv4: Set skb->dev for output route resolution
|
2018-12-20 16:42:39 -08:00 |
|
syncookies.c
|
|
|
|
sysctl_net_ipv4.c
|
net: provide a sysctl raw_l3mdev_accept for raw socket lookup with VRFs
|
2018-11-07 16:12:38 -08:00 |
|
tcp.c
|
tcp: fix code style in tcp_recvmsg()
|
2018-12-06 12:19:47 -08:00 |
|
tcp_bbr.c
|
tcp_bbr: update comments to reflect pacing_margin_percent
|
2018-11-08 20:46:17 -08:00 |
|
tcp_bic.c
|
|
|
|
tcp_bpf.c
|
bpf: sk_msg, sock{map|hash} redirect through ULP
|
2018-12-20 23:47:09 +01:00 |
|
tcp_cdg.c
|
tcp: cdg: use tcp high resolution clock cache
|
2018-10-15 22:56:42 -07:00 |
|
tcp_cong.c
|
|
|
|
tcp_cubic.c
|
|
|
|
tcp_dctcp.c
|
tcp: refactor DCTCP ECN ACK handling
|
2018-10-10 22:26:00 -07:00 |
|
tcp_dctcp.h
|
tcp: refactor DCTCP ECN ACK handling
|
2018-10-10 22:26:00 -07:00 |
|
tcp_diag.c
|
|
|
|
tcp_fastopen.c
|
|
|
|
tcp_highspeed.c
|
|
|
|
tcp_htcp.c
|
|
|
|
tcp_hybla.c
|
|
|
|
tcp_illinois.c
|
|
|
|
tcp_input.c
|
tcp: take care of compressed acks in tcp_add_reno_sack()
|
2018-11-30 13:26:53 -08:00 |
|
tcp_ipv4.c
|
tcp: md5: add tcp_md5_needed jump label
|
2018-11-30 13:28:03 -08:00 |
|
tcp_lp.c
|
|
|
|
tcp_metrics.c
|
mm: convert totalram_pages and totalhigh_pages variables to atomic
|
2018-12-28 12:11:47 -08:00 |
|
tcp_minisocks.c
|
|
|
|
tcp_nv.c
|
|
|
|
tcp_offload.c
|
net: use indirect call wrappers at GRO transport layer
|
2018-12-15 13:23:02 -08:00 |
|
tcp_output.c
|
tcp: handle EOR and FIN conditions the same in tcp_tso_should_defer()
|
2018-12-10 12:09:15 -08:00 |
|
tcp_rate.c
|
|
|
|
tcp_recovery.c
|
|
|
|
tcp_scalable.c
|
|
|
|
tcp_timer.c
|
tcp: change txhash on SYN-data timeout
|
2019-01-10 16:55:41 -05:00 |
|
tcp_ulp.c
|
tcp, ulp: remove socket lock assertion on ULP cleanup
|
2018-10-16 12:38:41 -07:00 |
|
tcp_vegas.c
|
|
|
|
tcp_vegas.h
|
|
|
|
tcp_veno.c
|
|
|
|
tcp_westwood.c
|
|
|
|
tcp_yeah.c
|
|
|
|
tunnel4.c
|
net: Convert protocol error handlers from void to int
|
2018-11-08 17:13:08 -08:00 |
|
udp.c
|
net: udp: prefer listeners bound to an address
|
2018-12-14 15:55:20 -08:00 |
|
udp_diag.c
|
net: diag: document swapped src/dst in udp_dump_one.
|
2018-10-28 19:27:21 -07:00 |
|
udp_impl.h
|
net: Convert protocol error handlers from void to int
|
2018-11-08 17:13:08 -08:00 |
|
udp_offload.c
|
udp: use indirect call wrappers for GRO socket lookup
|
2018-12-15 13:23:02 -08:00 |
|
udp_tunnel.c
|
udp_tunnel: add config option to bind to a device
|
2018-12-03 14:15:26 -08:00 |
|
udplite.c
|
net: Convert protocol error handlers from void to int
|
2018-11-08 17:13:08 -08:00 |
|
xfrm4_input.c
|
|
|
|
xfrm4_mode_beet.c
|
|
|
|
xfrm4_mode_transport.c
|
|
|
|
xfrm4_mode_tunnel.c
|
|
|
|
xfrm4_output.c
|
|
|
|
xfrm4_policy.c
|
|
|
|
xfrm4_protocol.c
|
net: Convert protocol error handlers from void to int
|
2018-11-08 17:13:08 -08:00 |
|
xfrm4_state.c
|
|
|
|
xfrm4_tunnel.c
|
|
|